Related Threat Clusters
-
TA416 Resumes Cyber Espionage Against European Governments Amid Geopolitical Tensions
Chinese state-backed group TA416 has reemerged with intensified cyber espionage campaigns targeting European governments, following a quiet period since 2023. Proofpoint reported that the group's renewed activity began…
9 articles · Updated April 1, 2026 -
Webworm APT Expands Operations to Europe with New Backdoors
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
12 articles · Updated May 20, 2026 -
HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth
The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a…
10 articles · Updated August 14, 2026 -
Operation CamelClone Targets Governments with Sophisticated Espionage Tactics
Operation CamelClone is a sophisticated cyber espionage campaign targeting government agencies and defense institutions in Algeria, Mongolia, Ukraine, and Kuwait. The attackers use spear-phishing emails containing…
2 articles · Updated March 17, 2026 -
Mustang Panda Espionage Campaigns Target India's Government and Energy Sectors
In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering…
2 articles · Updated June 30, 2026 -
Operation Synergia III Dismantles 45,000 Malicious IPs, Arrests 94 Worldwide
An international cybercrime operation, Operation Synergia III, coordinated by INTERPOL, has dismantled over 45,000 malicious IP addresses and servers linked to phishing, malware, and ransomware attacks. The operation,…
29 articles · Updated March 13, 2026 -
Foot-and-Mouth Disease Outbreak Sparks Culling in Russia and China
A significant outbreak of foot-and-mouth disease (FMD) has been reported in China's Xinjiang region, prompting immediate border control measures and livestock culling. This outbreak follows extensive cattle culling in…
2 articles · Updated April 3, 2026 -
Global Anti-Fraud Operation Nets 5,811 Arrests and $293 Million Seized
Operation First Light 2026, coordinated by INTERPOL, led to the arrest of 5,811 suspects and the interception of $293 million in illicit assets across 97 countries. This operation, which ran from January 15 to April 30,…
34 articles · Updated July 9, 2026 -
PlugX USB Worm Variant Spreads Globally via DLL Sideloading
A new variant of the PlugX USB worm is causing infections across multiple continents, utilizing DLL sideloading and USB-based propagation techniques to remain undetected. Initially identified in Papua New Guinea in…
2 articles · Updated April 14, 2026 -
GopherWhisper APT Targets Mongolia Using Cloud Tools for Espionage
The Chinese APT group known as GopherWhisper has been identified as targeting the Mongolian government using multiple cloud-based tools for espionage. Active since November 2023, the group has backdoored at least 12…
8 articles · Updated April 24, 2026
Recent Intelligence Reports
- Threat Landscape For Industrial Automation Systems Q2 2026 — ics-cert.kaspersky.com · August 27, 2026
- HoneyMyte deploys upgraded CoolClient backdoor in cyber-espionage ... — Kaspersky · August 14, 2026
- APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel — Securelist · August 14, 2026
- Over 5,800 arrests, USD 293 million intercepted in global fraud bust — Interpol.Int · July 9, 2026
- Over 5,800 arrests, USD 293 million intercepted in global fraud bust — Interpol.Int · July 9, 2026
- Digital frontline of East Asia security regime — Koreatimes.Co.Kr · July 2, 2026
- G0129 — attack.mitre.org · June 29, 2026
- Putin Seeks To Unblock Stalled Gas Pipeline In Talks With Xi In Beijing Bloomberg — unn.ua · May 20, 2026